CVE-2021-44650: High severity manageengine m365 manager plus vulnerability
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44650?
CVE-2021-44650 is a vulnerability in Zoho ManageEngine M365 Manager Plus before Build 4419 that allows remote command execution when updating proxy settings.
How severe is CVE-2021-44650?
CVE-2021-44650 has a severity rating of 7.2 (High).
What is the affected software?
The affected software is Zoho ManageEngine M365 Manager Plus versions up to and including 4.4, specifically 4.4-build4400 to 4.4-build4418.
How can the vulnerability be fixed?
To fix the vulnerability, users should update to Build 4419 of Zoho ManageEngine M365 Manager Plus.
Where can I find more information about CVE-2021-44650?
More information about CVE-2021-44650 can be found at the following link: [Zoho ManageEngine M365 Manager Plus Release Notes](https://www.manageengine.com/microsoft-365-management-reporting/release-notes.html?Build=4419)